← Back to browse · API

CVE-2021-25915

Severity
CRITICAL
CVSS
9.8
EPSS
0.03507
Risk score
40.43
CISA KEV
No
PoC
No
Published
2021-03-09
Modified
2025-04-30
First seen
2026-08-07
Aliases
EUVD-2022-1986, GHSA-2GQW-Q9R9-7F79
Products
n/a:changeset 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.1.0, 0.2.0, 0.2.1, 0.2.3, 0.2.4, 0.2.5
Sources
euvd EUVD-2022-1986

Description

Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.

References